CVE-2026-32690

Secrets in Variables saved as JSON dictionaries were not properly redacted - in case thee variables were retrieved by the user the secrets stored as nested fields were not masked. If you do not store variables with sensitive values in JSON form, you are not affected. Otherwise please upgrade to Apache Airflow 3.2.0 that has the fix implemented
Configurations

Configuration 1 (hide)

cpe:2.3:a:apache:airflow:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-04-18 07:16

Updated : 2026-06-17 10:36


NVD link : CVE-2026-32690

Mitre link : CVE-2026-32690

CVE.ORG link : CVE-2026-32690


JSON object : View

Products Affected

apache

  • airflow
CWE
CWE-668

Exposure of Resource to Wrong Sphere